Many small business owners think ransomware crews only chase large firms. The real pattern is different. Small businesses face more ransomware attacks by volume. They often have valuable data but no full-time security team.
A company with 22 people can be an ideal target. It may hold payroll data, client files, supplier records, and cash. It may also have a public trail that takes only an hour to map.
This walkthrough shows how such an attack can unfold over one week. The company is a composite. Still, the methods reflect current threat reports. The attack costs just $14 and about six hours of work.
The good news is that five common controls could stop it. Many of those controls may already be part of the security tools your business pays for.
Monday: The Attacker Picks a Small Business
The attacker works regular hours and targets only a few firms each month. Companies with 10 to 50 workers offer a useful balance.
Large firms often have security teams, lawyers, and response plans. Very small firms may not hold enough money or data. A 22-person services firm sits between those two groups.
The attacker starts with public records. State registries, local license records, and public contract awards can expose useful details. One search may show the company name, owner, registered agent, recent contract value, and project contact.
A clean security record may not bring comfort. The attacker may see it as a sign that old passwords still work. It may also suggest that staff have had little reason to learn how attacks look.
No breach or secret tip is needed. Public data is enough to start.
Tuesday: Public Profiles Reveal the Team
The attacker spends about 40 minutes mapping the company with a web browser.
LinkedIn lists eight workers and their job titles. The office manager says she handles payroll, supplier bills, and accounts payable. Another administrator joined 14 months ago. The owner has a quiet profile and few connections.
An old Facebook post lists staff names and photos. A public filing confirms the owner’s full legal name. Past job ads may also reveal which finance tools the company uses.
The attacker can now answer key questions:
- Who handles payments?
- Who can approve a transfer?
- Who has access to finance systems?
- Who is busy enough to rush through an email?
The office manager becomes the main target. She has access to money and key systems. Her inbox is also likely to be busy. A routine-looking message may not receive a close review.
The attacker still has not spent any money.
Wednesday: Stolen Credentials Cost $14
The next step involves stealer logs. These are bundles of stolen login data. Malware often collects the data from a personal computer. It may record passwords, browser sessions, and saved login tokens.
The stolen data can remain useful for months or years. Buyers can search underground markets by a company’s email domain.
In this example, the attacker finds two results. One includes the office manager’s work email and a saved password. The other includes a personal Gmail address linked to the owner’s family.
The package costs $14 and takes four minutes to buy.
The office manager’s password follows a common pattern. It combines a name, a year, and a symbol. A free check through Have I Been Pwned shows that the same password appeared in an old retail breach. It has not been changed.
The family member’s password also appears across several accounts. Small changes separate the versions. One version works for the company’s Microsoft 365 account.
A second sign-in step still protects the inbox. The attacker must now get past multi-factor authentication, or MFA.
Thursday: MFA Is Bypassed With a Fake Sign-In Page
MFA blocks many attacks. Yet the type of MFA matters.
Simple push spam is less useful now. Microsoft turned on number matching for Microsoft Authenticator push requests by default in May 2023. A user must type a number from the login screen. They cannot just tap an approval button.
The attacker uses adversary-in-the-middle phishing instead. This is also called AiTM phishing.
The office manager gets an email that looks like a normal Microsoft password notice. The message links to a fake sign-in page that copies the real page.
When she enters her password, the fake page passes it to Microsoft. It also passes along the MFA step. Microsoft accepts the login and creates a session token. The attacker captures that token.
The office manager sees what looks like a normal result. The attacker now has a valid session in a separate browser.
The attacker also tried a phone call as a backup. He posed as the company’s IT provider. He used a provider name found in an old public review. The receptionist did not give access, but the call shows how public details can support a convincing story.
By Thursday night, the attacker is inside the office manager’s Microsoft 365 account. He creates a rule that sends copies of her email to an outside address. Then he waits.
Friday: The Attacker Studies the Business
The attacker reads email for 36 hours before locking any files. This gives him time to learn how much pressure the business can bear.
He finds a cyber insurance policy with a $250,000 cyber limit. A bank record shows about $180,000 in the business account at month end. An emailed quote contains the client list.
He also finds a message about a city project. The project begins in three weeks and has a firm deadline. A delay could harm the business.
These details help him set a $65,000 ransom. He believes the company can reach that amount and may pay to avoid a longer delay.
The attack starts at 2:47 p.m. on Friday. The timing is planned. The bookkeeper leaves at 3 p.m. The owner is at a job site. Both facts came from messages and calendar data.
By the time the team understands the problem, it is Friday evening. Shared files are locked. A ransom note appears on office screens.
The attacker spent $14 and about six hours across the week.
Five Controls That Could Stop the Attack
1. Block Weak and Reused Passwords
The first opening was an old password. Have I Been Pwned offers a free way to check known breach data. Microsoft Entra password protection can also block weak or commonly exposed passwords.
A password manager helps each worker use a unique password for every account. That limits the value of a stolen password. One exposed login should not unlock several systems.
2. Use Phishing-Resistant MFA
Number matching helps stop simple approval spam. It does not fully stop fake sign-in pages that steal session tokens.
Stronger choices include FIDO2 security keys, passkeys, and Windows Hello for Business. These options resist phishing because they link access to the real service and approved device.
Conditional Access can add another check. It can require a managed or approved device. That may make a stolen session token useless on the attacker’s computer.
Microsoft Defender for Office 365 can also help detect phishing messages before a worker opens them.
3. Block External Email Forwarding
The attacker learned about cash, insurance, clients, and deadlines through copied email. Microsoft 365 admins can block outside forwarding rules for the whole tenant.
With that setting in place, the hidden rule would fail. The attacker might still try to lock files. Yet he would have far less information about the company’s money and plans.
4. Review the Alerts You Already Receive
Microsoft Defender for Business can alert an admin when someone creates a new forwarding rule. Microsoft 365 Business Premium includes this tool.
An alert only helps when someone sees it. The business needs to know where security alerts go and who reviews them. A watched alert could expose the attacker on Thursday night, well before the files are locked.
For many small firms, the best next step is not another product. It is better use of tools that are already in place.
5. Limit Detail in Public Staff Profiles
A business cannot remove state records or public contract awards. It can review the details staff share about their roles.
The office manager’s public profile made her the clear target. It showed that she handled payroll, bills, and supplier payments.
Talk with staff about how much job detail they publish. Keep the talk practical. The aim is not to ban social media. It is to avoid giving attackers a free map of access and authority.
Three Questions to Ask Your IT Provider
These questions cover the main gaps in the example:
- Do we use FIDO2 keys, passkeys, or Windows Hello for Business for finance, admin, and executive accounts?
- Is external email forwarding blocked across our Microsoft 365 tenant?
- Where do our security alerts go, and who reviews them?
Your provider should be able to give clear answers. If a control is missing, ask who will add it and when.
Common Questions About Small Business Ransomware
Do Ransomware Crews Target Small Businesses?
Yes. Small and mid-sized firms offer a strong mix of useful data and limited defense. Companies with about 10 to 50 workers may hold valuable files but lack a dedicated security team.
What Is AiTM Phishing?
AiTM phishing uses a fake page that sits between the user and a real sign-in service. It passes the login steps to the real service, then steals the session token that comes back. This can defeat some forms of MFA.
What Is a Stealer Log?
A stealer log is a package of data taken from a device infected with malware. It can include passwords, cookies, and login tokens. In this example, the package costs $14.
Can Free or Existing Tools Help?
Yes. Have I Been Pwned is free. External forwarding blocks and security alerts may already be available through Microsoft 365 settings and Business Premium tools. The main task is to turn the controls on and make sure someone watches the alerts.
Take the First Three Steps
Start with the three questions for your IT provider. Then check whether high-risk staff use phishing-resistant MFA. Block outside email forwarding and confirm that a person reviews security alerts.
These steps address the same gaps that let the example attack grow from a $14 password purchase into a ransomware crisis.
If this attack sounds close to your own setup, contact Caldera Cybersecurity for a security consultation. We can help you confirm which controls are active and where the gaps remain.

